Hackers exploit zero-day Common Log File System vulnerability to plant ransomware

Hackers exploit zero-day Common Log File System vulnerability to plant ransomware

  • Microsoft said it observed a threat actor known as Storm-2460 abuse a use after free flaw in Windows Common Log File System Driver
  • The flaw is used to deploy PipeMagic, which is then used to deliver ransomware
  • Users are advised to install the released patch immediately

Cybercriminals are abusing a post-compromise zero-day vulnerability in the Windows Common Log File System (CLFS) to deploy ransomware.

Earlier this week, Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) published a new in-depth report, describing how a flaw tracked as CVE-2025-29824 is being used in cyberattacks.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *


Enable Notifications OK No thanks